Attachment_3_-_Agency_Specific_Clauses.docx

DOCX document 105 KB Posted

Attached to
Medicare Physician Fee Schedule (PFS) Public Comment Support. Federal contract opportunity
Solicitation number
191552
Issued by
Department of Health and Human Services Centers for Medicare and Medicaid Services

About this file

Agency Specific Clauses

View the file

Other files for this federal contract opportunity

Other files attached to Medicare Physician Fee Schedule (PFS) Public Comment Support., newest first.
File Type Posted
Cover_Letter_-_191552.pdf PDF
Total_list_of_QA_from_the_Contractors_all_Answered.xlsx XLSX spreadsheet
Attachment_1_-_PFS_Public_Comment_SOW.docx DOCX document
Attachment_2_-_QIEC.docx DOCX document
Attachment_3_-_Agency_Specific_Clauses.docx DOCX document
Attachment_2_-_QIEC.docx DOCX document
Attachment_1_-_PFS_Public_Comment_SOW.docx DOCX document
Attachment_7-_QA_Template.xlsx XLSX spreadsheet
Attachment_5_-_Personal_Conflicts_of_Interest_Financial_Disclosure.docx DOCX document
Attachment_4_-_Contractor_Business_Ethics_COI_and_Compliance_Program_Requirements.docx DOCX document
Cover_Letter_-_191552.pdf PDF
Attachment_6_-_PPQ.docx DOCX document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 3 - Agency Specific Clauses

RFQ 191552

Medicare Physician Fee Schedule (PFS) Public Comment Support

1. PERIOD OF PERFORMANCE (JAN 2014)

The period of performance of this task order is:

TBD

2. PAYMENTS – VOUCHERS – Cost Reimbursement and Non-Commercial Labor Hour/Time & Materials Contracts (Sept 2018)

a. GENERAL: The Contractor may submit to the Government a voucher or Standard Form 1034, Public Voucher for Purchases and Services Other Than Personal, for payment in accordance with the instructions below.

b. BANKING CHANGES: The contractor shall notify CMS’ Division of Accounting Operations of all banking and address changes made in SAM via the following email address: CCRChanges@cms.hhs.gov.

c. CONTENT OF VOUCHER: FAR 32.905 Payment Documentation and Process, provides the required content for a proper voucher. In addition to the requirements of FAR 32.905, the following items shall also be included on the voucher to be considered proper:

· Line item number (i.e. CLIN/SLIN as applicable)

· Contractor’s DUNS Number

· Period of performance or delivery date of goods or services provided.

· Additional items identified in Section J.x<CO/CS – Delete this bullet if no other billing instructions are provided – For example, system inputs (CMS-ARTS, FIVS, etc.)>

d. VOUCHER SUBMISSION: Vouchers shall be submitted via email in electronic format as follows:

To…: InvoiceSubmission@cms.hhs.gov

Cc…:Please “Cc…” your respective Contract Specialist (CS) and Contracting Officer’s Representative (COR) as follows:

· Contract Specialist – TBD@CMS.HHS.Gov; and

· COR - TBD@CMS.HHS.Gov.

Subject Line: The email subject line shall contain the following information: Contract Number, Task/Delivery Order Number (if applicable), Voucher Number, and Notification of Final Invoice (if applicable).

PLEASE DO NOT INCLUDE ANY ADDITIONAL INFORMATION IN THE SUBJECT LINE, as doing so may delay internal processing of your invoice for payment.

Attachments: Voucher attachments shall be submitted in .pdf format. Only one voucher shall be attached per email. The first page of the attachment shall be the invoice, followed by any supporting documents as applicable.

<Note to CO/CS – A single invoice can provide billing information against multiple CLINs or deliverable Subline Items.>

e. PAYMENTS: The Government shall make interim payments on all vouchers (subject to later audit) in accordance with the following clauses, as applicable:

· FAR 52.232-33 Payments by Electronic Funds Transfer – System for Award Management,

· FAR 52.216-7, Allowable Cost & Payment, and

· FAR 52.232-7, Payments under Time-and-Materials and Labor-Hour Contracts

Payment shall be made upon acceptance by the Contracting Officer’s Representative (COR) of the required supplies/services in accordance with the applicable FAR Inspection and Acceptance clause and the Contracting Officer’s approval.

Reimbursement for vouchers submitted under this contract shall be made no later than 30 calendar days after receipt of an acceptable voucher from the Contractor requested at the paying office designated above. CMS will make every effort to accelerate payments to small businesses and prime contractors with small business subcontractors.

f. INTEREST ON OVERDUE PAYMENT: The Prompt Payment Act, Public Law 97-177 (96 Stat.85.31 U.S.C. 1801) is applicable to payments under this contract and requires the payment of interest on payments made more than 30 calendar days after receipt of a proper voucher by the Division of Accounting Operations.

3. CONTRACTOR PAST PERFORMANCE EVALUATION(S) (OCT 2014)

a. General:

In accordance with Federal Acquisition Regulation (FAR) 42.15, Contractor Performance Information, past performance evaluations shall be prepared at least annually and at the time the work under a contract or order is completed. Additional interim performance evaluations may be prepared at Contracting Officer discretion, as necessary.

CMS will utilize the Contractor Performance Assessment Reporting System (CPARS), the Government-wide evaluation reporting tool for all past performance reports on contracts and orders, as appropriate. CPARS is a secure Internet website located at https://www.cpars.gov.

b. CPARS Process:

1. CPARS Training: Contractors may obtain CPARS training material and register for on-line training https://www.cpars.gov.

2. Post-Award Contract Registration: CMS is responsible for registering the contract in CPARS within 30 calendar days of contract award. The Contractor shall:

i. Designate at least one (1) point of contact that will be responsible for serving as the Contractor’s Representative (CR). Additional CRs may also be identified; and,

ii. Provide the CMS Contract Specialist with the name(s) and email address(es) of the CPARS point(s) of contact.

Once CMS registers the contract in CPARS, the CR(s) will receive an automated CPARS email message that contains User IDs and instructions for creating a password for future past performance evaluation processing.

3. Interim, Annual and Final Past Performance Evaluation Reports:

a. Issuing the Evaluation: Once the CMS Assessing Official (AO) issues an evaluation to the Contractor in CPARS, the CR(s) will receive an email instructing them to login to CPARS to review the evaluation.

b. Contractor Comments: The CR has the option to provide comments on the evaluation, indicate if they concur or do not concur with the evaluation, sign, and then return the evaluation to the AO. The CR has a total of 60 days following the AO’s evaluation signature date to submit comments. If the CR submits comments within the first 14 days following the AO’s signature date and the AO closes the evaluation, the evaluation will become available in Past Performance Information Retrieval System - Report Card (PPIRS-RC) within 1 day.

On day 15 following the AO’s evaluation signature date, the evaluation will become available in PPIRS-RC with or without CR comments and whether or not it has been closed by the AO. If no CR comments have been sent and the evaluation has not been closed, it will be marked as “Pending” in PPIRS-RC.

If the CR sends comments at any time prior to 61 days following the AO’s evaluation signature date, those comments will be reflected in PPIRS-RC within 1 day. On day 61 following the AO’s evaluation signature date, the CR will be “locked out” of the evaluation and may no longer send comments.

4. CONTRACTOR WORK PERFORMED OUTSIDE THE UNITED STATES AND ITS TERRITORIES (APR 2016)

To comply with requirements of Homeland Security Presidential Directive -12 (HSPD-12) and Personal Identity Verification (PIV) of Federal Employees and Contractors, CMS must achieve appropriate security assurance for multiple CMS information systems by efficiently verifying the claimed identity of individuals working on the contract. The Contractor and its subcontractor(s) shall not perform any activities under this contract, including the transmission of data or other information, outside of the United States (U.S.) and its Territories without the prior written approval of the Contracting Officer. If work must be performed outside the U.S., the Contractor shall submit a request to the Contracting Officer, in writing, at least 45 calendar days prior to the work beginning.

The Contracting Officer will consider the following factors in making a decision whether to authorize the performance of work outside the U.S. and its Territories:

1. Statement of Work requirements, which are being requested to be completed outside the U.S. and its Territories;

2. Total projected dollar value of the work to be performed outside the U.S.;

3. The desired country/location where the work will be performed;

4. FAR Part 25, Foreign Acquisitions, and all other laws and regulations applicable to the performance of work outside the United States;

5. Whether the contractor and/or its subcontractor(s) have plans in place to adequately protect and secure CMS data, as well as abide by all applicable laws and regulations when work is performed outside of the U.S. and its Territories. Plans shall include -

a. Adequate contract terms regarding system security;

b. Adequate contract terms regarding the confidentiality and privacy requirements for information and data protection;

c. Adequate contract terms that are otherwise relevant, including the requirements of the Statement of Work;

d. The Contractor’s corporate compliance plan and internal policies and procedures designed to prevent and detect violations of applicable law, regulations, rules and ethical standards by employees, agents and others; and,

6. Whether the approval would be in best interests of the United States.

The Contractor’s request for authorization to perform work outside the U.S. shall demonstrate that the performance of the work outside the U.S. satisfies all of the above factors. Contracting Officer approval to perform work outside the U.S. may require additional Statement of Work requirements, additional contract terms and conditions and/or Federal Acquisition Regulation (FAR) clauses to be incorporated into the contract.

5. GOVERNMENT REPRESENTATIVES AND RESPONSIBILITIES (JUL 2016)

Following are the Government Representatives and their respective roles and responsibilities on this contract:

a. Contracting Officer

As defined in Federal Acquisition Regulation (FAR) 2.101, Definitions, and in accordance with FAR 1.602-1, Authority, “Contracting officers have authority to enter into, administer, and/or terminate contracts and make related determinations and findings.” There is no other authorized representative or any other Administrative Contracting Officer assigned to this contract to carry out a Contracting Officer’s duties, except for technical direction assigned to the Contracting Officer’s Representative, if applicable.

The Contracting Officer is: Rico Batte

Centers for Medicare & Medicaid Services Office of Acquisition & Grants Management Acquisition Support Group Division of Medicare Support Contracts ATTN: Rico Batte 7500 Security Blvd.

Mail-stop: B2-20-25 Baltimore, MD 21244-1850

Phone: 410-786-7934 Email Address: Rico.Batte@cms.hhs.gov

b. Contract Specialist

Notwithstanding any of the other provisions of this Contract, the Contract Specialist will assist the Contracting Officer with his/her responsibilities as defined in the FAR.

The Contract Specialist is Cheryl Caldwell

Centers for Medicare & Medicaid Services Office of Acquisition & Grants Management Acquisition Support Group Division of Medicare Support Contracts ATTN: Cheryl Caldwell 7500 Security Blvd.

Mail-stop: B2-21-15 Baltimore, MD 21244-1850

Phone: 410-786-8900 Email Address: Cheryl.Caldwell@cms.hhs.gov

c. Contracting Officer’s Representative

The Contracting Officer’s Representative (COR), as defined in FAR 2.101, Definitions, is:

Centers for Medicare & Medicaid Services Group: TBD Division: TBD

ATTN: TBD

7500 Security Blvd.

Mail-stop: None Baltimore, MD 21244-1850

Phone: TBD Email Address: TBD In accordance with FAR 1.602-2(d), Responsibilities, the COR’s delegated responsibilities are identified in the Contracting Officer’s appointment memorandum, a copy of which will be furnished to the contractor.

Technical direction must be within the general scope of the work stated in the contract. The term "technical direction" is defined to include, without limitation, the following:

Directions to the Contractor which direct the contract effort, shift work emphasis between work areas or tasks, require pursuit of certain lines of inquiry, fill in details or otherwise serve to accomplish the contractual technical requirements as identified in the Statement of Work or Performance Work Statement; or Provision of information to the Contractor, which assists in the interpretation of drawings, specifications, or technical portions of the work description.

The COR does not have the authority to:

1. Make changes to contract terms and conditions;

2. Direct the contractor to perform work or make deliveries not specifically required under the contract;

3. Waive or relax the Government’s rights with regard to the Contractor’s compliance with the specifications, price, delivery or any other terms or conditions of the contract;

4. Make any commitments or approve any actions that would create any financial obligation on the part of the Government; or

5. Issue direction that constitutes a “change” as defined in:

FAR 52.243-1, Changes – Fixed Price;

FAR 52.243-2, Changes – Cost Reimbursement;

FAR 52.243-3, Changes – Time and Material and Labor Hour;

FAR 52.243-4, Changes; or, FAR 52.243-5, Changes and Changed Conditions.

All technical direction shall be issued in writing by the COR or, if issued verbally, shall be confirmed in writing by the COR within five (5) business days after issuance.

The Contractor shall proceed promptly with the performance of technical direction duly issued by the COR within the scope of his/her authority.

If, in the opinion of the Contractor, any instruction or direction issued by a Government representative constitutes a change to the contract or constitutes a “Change Order” as defined in FAR 2.101, Definitions, the Contractor shall follow the instructions identified in FAR 52.243-7 Notification of Changes.

6. CMS INFORMATION SECURITY (APR 2013)

All CMS information shall be protected from unauthorized access, use, disclosure, duplication, modification, diversion, or destruction, whether accidental or intentional, in order to maintain the security, confidentiality, integrity, and availability of such information. Therefore, if this contract requires the contractor to provide services (both commercial and non-commercial) for Federal Information/Data, to include any of the following requirements:

· Process any Information/Data; or

· Store any Information/Data (includes “Cloud” computing services); or

· Facilitate the transport of Information/Data; or

· Host/maintain Information/Data (including software and/or infrastructure developer/maintainers); or

· Have access to, or use of, Personally Identifiable Information (PII), including instances of remote access to, or physical removal of, such information beyond agency premises or control, The contractor shall become and remain compliant with the requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html. The requirements cover all CMS contracts and associated deliverables, which are required on a “per contractor” basis.

The contractor shall ensure that the following Federal information security standards are met for all of its CMS contracts:

· Federal Information Security Management Act (FISMA) – FISMA information can be found at http://csrc.nist.gov/groups/SMA/fisma/index.html. FISMA requires each Federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source; and,

· Federal Risk and Authorization Management Program (FedRAMP) – FedRAMP information can be found at http://www.gsa.gov/portal/category/102371. The FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

The Contractor shall include in all awarded subcontracts the FISMA/FedRAMP compliance requirements set forth at the CMS Information Security website at https://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Info-Security-Library-Items/CMS-Information-Security-Contract-Clause-Provision.html..

7. HIPAA BUSINESS ASSOCIATE CLAUSE (OCT 2014)

All Protected Health Information (PHI), as defined in 45 C.F.R. §160.103, that is relevant to this Contract, shall be administered in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA," 42 U.S.C. § 1320d), as amended, as well as the corresponding implementing regulations and this HIPAA Business Associate Clause.

a. Definitions:

All terms used herein and not otherwise defined, shall have the same meaning as in HIPAA, as amended, and the corresponding implementing regulations. Non-HIPAA related provisions governing the Contractor's duties and obligations, such as those under the Privacy Act and any applicable data use agreements, are generally covered elsewhere in the Contract.

The following definitions apply to this Contract Clause:

"Business Associate'' shall mean the Contractor (and/or the Contractor’s subcontractors or agents) if/when it uses individually identifiable health information on behalf of CMS, i.e. PHI, to carry out CMS’ HIPAA-covered functions.

"Covered Entity" shall mean the portions of CMS that are subject to the HIPAA Privacy Rule.

"Secretary" shall mean the Secretary of the Department of Health & Human Services or the Secretary's designee.

b. Obligations and Activities of Business Associate:

Except as otherwise provided in this Contract, Business Associate, as defined above, shall only use or disclose PHI on behalf of, or to provide services to, Covered Entity in accordance with this Contract and the HIPAA Privacy and Security Rules.

Business Associate shall document in writing the policies and procedures that will be used to meet HIPAA requirements. The policies and procedures shall include the following, at a minimum:

1. Business Associate shall not:

i. Use or disclose PHI that is created, received, maintained or transmitted by Business Associate from, or on behalf of, Covered Entity other than as permitted or required by this Contract or as required by law;

ii. Sell PHI; or,

iii. Threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action against any individual for:

A. Filing a complaint under 45 CFR § 160.306;

B. Testifying, assisting or participating in an investigation, compliance review, proceeding or hearing under 45 CFR Part 160; or

C. Opposing any act or practice that is unlawful under HIPAA, provided there is a good faith belief that the practice is unlawful, the manner of opposition is reasonable, and the opposition does not involve the disclosure of PHI in violation of subpart E of Part 164.

2. Business Associate shall:

i. Have a security official who will be responsible for development and implementation of its security policies and procedures, including workforce security measures, to ensure proper security awareness and training (including security incident response and reporting), and security incident procedures, in accordance with this Contract, including this HIPAA Business Associate Clause and the Contract’s clause entitled “CMS Information Security.”

ii. Use administrative, physical and technical safeguards to prevent use or disclosure of PHI created, received, maintained or transmitted by Business Associate from, or on behalf of Covered Entity only as provided for by this Contract. In doing so, it shall implement policies and procedures to address the following and, where applicable, ensure that such policies and procedures are also in conformance with this Contract’s clause entitled “CMS Information Security:”

A. Prevent, detect, contain and correct security violations through the use of:

a. Risk analyses (including periodic technical and nontechnical evaluations);

b. Appropriate risk management strategies, including system activity review;

c. Information access procedures for approving individual’s access rights to PHI (including the implementation of workforce security measures to ensure continued appropriate role-based access to PHI), and technical policies and procedures to ensure compliance with grants of access (including unique user identification and tracking of users) and;

d. The imposition of sanctions for violations.

B. Limit physical access to its electronic information systems and the facility or facilities in which they are housed.

C. Implement policies, procedures and physical security measures that will limit access to PHI through workstations and other devices, including access through mobile devices.

D. Implement media controls covering the movement of devices containing PHI within or outside of the Business Associate’s facility as well as the disposal and reuse of media containing PHI.

E. Implement appropriate administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability (including the use of contingency plans) of any electronic protected health information ("EPHI") it creates, receives, maintains or transmits from, or on behalf of the Covered Entity to prevent impermissible use, disclosure, maintenance or transmission of such EPHI. In the establishment of such safeguards, Business Associate shall consider its size, complexity and capabilities, as well as its technical infrastructure, and its hardware and software security capabilities.

iii. Assess, and implement, where appropriate, any addressable implementation specifications associated with applicable PHI security standards.

iv. Mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of the requirements of this Contract.

v. Comply with the following Incident Reporting:

A. Report to Covered Entity any security incident/breach involving unsecured PHI, of which it becomes aware, including those of its agents and subcontractors. The Business Associate shall report any violation of the terms of this contract involving PHI and any security incidents/breaches involving unsecured PHI to CMS within one (1) hour of discovery in accordance with the CMS Risk Management Handbook (RMH), specifically “RMH Vol II Procedure 7-2 Incident Handling Procedure” and “RMH Vol III Standard 7-1 Incident Handling.” These procedures can be found at http://www.cms.gov/Research-Statistics-Data-and-Systems/CMS-Information-Technology/InformationSecurity/Information-Security-Library.html In addition, the Business Associate will also notify the CMS Contracting Officer and the Contracting Officer’s Representative (COR) by email within one (1) hour of identifying such violation or incident.

B. Upon Covered Entity's knowledge of any material security incident/breach by Business Associate, Covered Entity will provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination clause of this Contract. See also paragraph D. Term of Clause below.

vi. Ensure that any agent or subcontractor agrees through a written contract, or other legally enforceable arrangement, to the same restrictions and conditions that apply through this HIPAA Contract Clause, when creating, receiving, maintaining or transmitting PHI from, or on behalf of, Covered Entity.

vii. Upon Covered Entity’s request:

A. Provide the Covered Entity or its designee with access to the PHI created, received, maintained or transmitted by Business Associate from or on behalf of the Covered Entity in the course of contract performance in order to ensure Covered Entity’s ability to meet the requirements under 45 CFR § 164.524.

B. Amend PHI as Covered Entity directs or agrees to pursuant to 45 CFR § 164.526.

viii. Make its facilities and any books, records, accounts, and any sources of PHI, including any policies and procedures, that are pertinent to ascertaining its own compliance with this contract or the Covered Entity’s compliance with the applicable HIPAA requirements, available to Covered Entity, or, in the context of an investigation or compliance review, to the Secretary for purposes of the Secretary determining Covered Entity's compliance with the various rules implementing the HIPAA.

ix. Document disclosures of PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

x. Provide to Covered Entity, or an individual identified by the Covered Entity, information collected under this Contract, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with 45 CFR § 164.528.

xi. Make reasonable efforts to limit the PHI it uses, discloses or requests to the minimum necessary to accomplish the intended purpose of the permitted use, disclosure or request.

c. Obligations of Covered Entity

Covered Entity shall notify Business Associate of any:

1. Limitation(s) in its Notice of Privacy Practices in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI;

2. Changes in, or revocation of, permission by an Individual to use or disclose their PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI; and,

3. Restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI.

d. Term of Clause

1. The term of this Clause shall be effective as of date of Contract award, and shall terminate when all of the PHI provided to Business Associate by the Covered Entity or a Business Associate of the Covered Entity, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity in accordance with “CMS Information Security” procedures. Business Associate shall not retain any PHI.

2. Security Incident/Breach:

Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall take action consistent with the terms of this Contract, and, as appropriate, the following:

i. Federal Acquisition Regulation (FAR) Contracts – Covered Entity may:

A. Terminate this Contract in accordance with FAR Part 49, Termination of Contracts, if the Business Associate does not cure the security incident/breach within the time specified by Covered Entity and/or cure is not possible; or, B. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

ii. Other Agreements –Covered Entity shall either:

A. Provide an opportunity for Business Associate to cure the breach or end the violation consistent with the termination terms of this Contract. Covered Entity may terminate this Contract for default if the Business Associate does not cure the breach or end the violation within the time specified by Covered Entity; or, B. Consistent with the terms of this Contract, terminate this Contract for default if Business Associate has breached a material term of this Contract and cure is not possible; or, C. If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

3. Returning or Destroying PHI:

Business Associate, as defined above, which includes subcontractors or agents of the Contractor, shall:

i. Upon expiration or termination of this Contract, for any reason, return or destroy all PHI received from Covered Entity or another Business Associate of the Covered Entity, as well as any PHI created, received, maintained or transmitted from or on behalf of Covered Entity, or another Business Associate of the Covered Entity, in accordance with this contract, including the “CMS Information Security” clause.

ii. In the event that Business Associate determines that returning or destroying the PHI is infeasible, provide to Covered Entity notification of the conditions that make return or destruction infeasible. Upon such notice that return or destruction of PHI is infeasible, Business Associate shall extend the protections of this Contract to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.

e. Miscellaneous

1. A reference in this Contract to a section in the Rules issued under HIPAA means the section as in effect or as amended.

2. The respective rights and obligations of Business Associate under paragraph D.3.b of the section entitled "Term of Clause" shall survive the termination of this Contract.

Any ambiguity in this Contract clause shall be resolved to permit Covered Entity to comply with the Rules implemented under HIPAA.

8. CMS SECURITY CLAUSE (APR 2016)

a. Applicability In accordance with OMB Memorandum M-05-24, Implementation of Homeland Security Presidential Directive 12 (HSPD-12): Policy for a Common Identification Standard for Federal Employees and Contractors, dated August 27, 2004, and Federal Information Processing Standard (FIPS) PUB Number 201-2, Personal Identity Verification (PIV) of Federal Employees and Contractors, CMS must achieve appropriate security assurance for multiple applications by efficiently verifying the claimed identity of individuals seeking physical access to Federally controlled government facilities and/or logical access to federally controlled information systems. Contractors that require routine physical access to a CMS facility and/or routine access to a CMS federally controlled information system will be required to obtain a CMS issued PIV, PIV-I or Locally Based Physical Access card. FIPS PUB 201-2 specifies the architecture and technical requirements for a common identification standard for Federal employees and Contractors.

When a PIV or PIV-I card is provided, it shall be used in conjunction with a compliant card reader and middleware for logical system access. The Contractor shall (1) Include FIPS 201-2 compliant, HSPD-12 card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR 52.204-9, Personal Identity Verification of Contractor Personnel.

b. Definitions

“Agency Access” means access to CMS facilities, sensitive information, information systems or other CMS resources.

“Applicant” is a Contractor employee for whom the Contractor submits an application for a CMS identification card.

“Contractor Employee” means prime Contractor and subcontractor employees who require agency access to perform work under a CMS contract.

“Official station”— As defined by Federal Travel Regulations, An area defined by the agency that includes the location where the employee regularly performs his or her duties or an invitational traveler’s home or regular place of business. The area may be a mileage radius around a particular point, a geographic boundary, or any other definite domain, provided no part of the area is more than 50 miles from where the employee regularly performs his or her duties or from an invitational traveler’s home or regular place of business. If the employee’s work involves recurring travel or varies on a recurring basis, the location where the work activities of the employee’s position of record are based is considered the regular place of work.

“Federal Identification Card” (or “ID card”) means a federal government issued or accepted identification card such as a Personal Identity Verification (PIV) card, Personal Identity Verification-Interoperable (PIV-I) card, or a Local-Based Physical Access Card issued by CMS, or a Local-Based Physical Access Card issued by another Federal agency and approved by CMS. “Issuing Office” means the CMS entity that issues identification cards to Contractor employees.

“Locally Based Physical Access Card” means an access Card that is graphically personalized for visual identification, that does not contain an embedded computer chip, and is only used for physical access.

“Local Security Servicing Organization” means the CMS entity that provides security services to the CMS organization sponsoring the contract, Division of Physical Security and Strategic Information (DPSSI).

“Logical Access” means the ability for the Contractor to interact with CMS information systems, databases, digital infrastructure, or data via access control procedures such as identification, authentication, and authorization.

“Personal Identity Verification (PIV) card,” as defined in FIPS PUB 201-2, is a physical artifact (e.g., identity card, “smart” card) issued to an individual that contains a PIV Card Application which stores identity credentials (e.g., photograph, cryptographic keys, digitized fingerprint representation) so that the claimed identity of the cardholder can be verified against the stored credentials by another person (human readable and verifiable) or an automated process (computer readable and verifiable).

“Personal Identity Verification-Interoperable (PIV-I) card” similar to a PIV card, is a physical artifact (e.g., identity card, “smart” card) issued to an individual that contains a PIV Card Application which stores identity credentials (e.g., photograph, cryptographic keys, digitized fingerprint representation) so that the claimed identity of the cardholder can be verified against the stored credentials by another person (human readable and verifiable) or an automated process (computer readable and verifiable). PIV-I cards are issued by a non-federal government entity to non-federal government staff. PIV-I cards are issued in a manner that allows federal relying parties to trust the cards. The PIV-I cards uses the same standards of vetting and issuance developed by the U.S. government for its employees

c. Screening of Contractor Employees

i. Contractor Screening of Applicants

1. Contractor Responsibility: The Contractor shall pre-screen individuals designated for employment under any CMS contract by verifying minimum suitability requirements to ensure that only qualified candidates are considered for contract employment. At the discretion of the government, the government reserves the right to request and/or review Contractor employee vetting processes. The federal minimum suitability requirements can be found below in section (c)(2)—Suitability Requirements, and are also contained in 5 CFR 731.202. The Contractor shall exercise due diligence in pre-screening all employees prior to submission to CMS for agency access.

2. Alien Status: The Contractor shall monitor an alien’s (foreign nationals) continued authorization for employment in the United States. If requested by the Agency, the Contractor shall provide documentation to the Contracting Officer (CO) or the Contracting Officer’s Representative (COR) that validates that the Employment Eligibility Verification (e-Verify) requirement has been met for each Contractor or sub-Contractor employee working on the contract in accordance with Federal Acquisition Regulation (FAR) 52.222-54 - Employment Eligibility Verification.

3. Residency Requirement: All CMS Contractor applicants shall have lived in the United States at least three (3) out of the last five (5) years prior to submitting an application for a Federal ID Card. CMS will process background investigations for foreign nationals in accordance with Office of Personnel Management (OPM) guidance. Contractor employees who worked for the U. S. Government as an employee overseas in a Federal or military capacity; and/or been a dependent of a U.S. Federal or military employee serving overseas, must be able to provide state-side reference coverage. State-side coverage information is required to make a suitability or security determination. Examples of state-side coverage information include: the state-side address of the company headquarters where the applicant’s personnel file is located, the state-side address of the Professor in charge of the applicant’s “Study Abroad” program, the religious organization, charity, educational, or other non-profit organization records for the applicant’s overseas missions, and/or the state-side addresses of anyone who worked or studied with the applicant while overseas.

4. Selective Service Registration: All males born after December 31, 1959, must meet the Federal Selective Service System requirements as established on www.sss.gov.

ii. Identification Card Application Process

ID Card Sponsor: The CMS Contracting Officer’s Representative (COR) will be the CMS ID card Sponsor and point of contact for the Contractor’s application for a CMS ID card. The COR will review and approve/deny the HHS ID Badge Request before the form is submitted to the CMS, Office of Support Services and Operations, (OSSO), Division of Personnel Security Services (DPS), for processing. If approved, an applicant may be issued either a Personal Identity Verification (PIV) or PIV- I card that meets the standards of HSPD-12 or a Local-Based Physical Access Card.

Contractor Application Required Submissions: All applicants shall submit an HHS ID Badge Request form for issuance of a Federal ID Card. Unless otherwise directed by the ID Card Sponsor or DPS, applicants are required to electronically submit the request form via CMS’ Enterprise User Administration (EUA) Electronic Front-end Interface (EFI) system, which is located at https://eua.cms.gov/efi. To assist users with the application process, a user’s guide is located at:https://www.cms.gov/About-CMS/Contracting-With-CMS/ContractingGeneralInformation/Contracting-Policy-and-Resources.html.

The EUA users guide link should be used to obtain the most current instructional guidance.

PIV Training: Contractors who need PIV or PIV-I card shall complete HHS PIV Applicant Training, which is found at https://www.cms.gov/About-CMS/Contracting-With-CMS/ContractingGeneralInformation/Contracting-Policy-and-Resources.html. A copy of the completion certificate shall be included with the EFI application.

CMS Applicant Evaluations: CMS will evaluate an applicant’s required access level. Once the review is complete and accepted for further processing, the applicant will be contacted by DPS to submit the below information, as applicable.

1. e-QIP: Contractor employees will be required to submit information into e-QIP, a web-based automated system that is designed to facilitate the processing of standard investigative forms used when conducting background investigations for Federal security, suitability, fitness and credentialing purposes.

2. Fingerprints: Instructions for obtaining fingerprints will be provided by CMS, OSSO, DPS.

3. OF 306: Contractor employees may be required to complete the Optional Form (OF) 306, Declaration for Federal Employment which can be found at https://www.opm.gov/forms/pdf_fill/of0306.PDF.

4. Access to Restricted Area(s): The CMS COR will initiate all Federal ID card holders’ physical access requests via Physical Access Control System (PACS) Central at https://pam.cms.local.

Suitability Requirements: CMS may decline to grant agency access to a Contractor employee including, but not limited to, any of the criteria cited below:

1. Misconduct or negligence in employment;

2. Criminal or dishonest conduct;

3. Material, intentional false statement, or deception or fraud in examination or appointment;

4. Refusal to furnish testimony as required by § 5.4 of 5 CFR 731.202;

5. Alcohol abuse, without evidence of substantial rehabilitation, of a nature and duration that suggests that the applicant or appointee would be prevented from performing the duties of the position in question, or would constitute a direct threat to the property or safety of the applicant or appointee or others;

6. Illegal use of narcotics, drugs, or other controlled substances without evidence of substantial rehabilitation;

7. Knowing and willful engagement in acts or activities designed to overthrow the U.S. Government by force; and

8. Any statutory or regulatory bar which prevents the lawful employment of the person involved in the position in question.

Badge Issuance: Upon approval of the badging application process and prior to starting work on the contract, applicants whose official station is located within 50 miles from CMS’ central office or one of its regional offices will be contacted to appear in person, at least two times (estimated at one hour for each visit), and shall provide two (2) original forms of identity source documents in order to generate the badge/ID. The identity source documents shall come from the list of acceptable documents included in FIPS 201-2, located at http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.201-2.pdf. At least one (1) document shall be a valid State or Federal government-issued picture ID. PIV-I mobile enrollment stations will be made available for applicants that have an official station more than 50 miles from CMS or any of its regional offices, and the employee will not need to travel to a CMS Office. The Contractor will be contacted by CMS for further instructions on the badging process in this scenario.

d. CMS Position Designation Assessment

CMS will assign a risk and sensitivity level designation analysis to the overall contract and/or to Contractor employee positions by category, group or individual. The risk and sensitivity level designations will be the basis for determining the level and type of personnel security investigations required for Contractor employees. At a minimum, the FBI National Criminal History Check (fingerprint check) must be favorably adjudicated. Additionally, the OPM e-QIP and other required forms must be accepted by DPS before a CMS identification card will be issued.

e. Post Badging Training Requirements:

Contractor employees that receive an HHS ID Badge are expected to complete the following online trainings each year, according to the timeframes indicated below, and annually thereafter. The below list is not all inclusive and the COR may indicate training that must be taken in addition to the below:

i. Security and Insider Threat Awareness and Training (30 days after receiving badge): This course outlines the role of Contractors with regard to protecting information and ensuring the secure operation of CMS federally controlled information systems. Estimated time to complete is one hour.

ii. Computer Based Training (CBT) (within 3 days of approved EUA account): This training offers several modules to familiarize contractor employees with features of CMS’ webinar service. Estimated time to complete is one hour.

f. Background Investigation and Adjudication

Upon contract award and receipt of an HHS ID Badge Request, CMS will initiate the Agency Access procedures, to include a background investigation.

CMS may accept favorable background investigation adjudications from other Federal agencies when there has been no break in service. A favorable adjudication does not preclude CMS from initiating a new investigation when deemed necessary. Each CMS sponsored Contractor shall use the OPM e-QIP system to complete any required investigative forms.

The Contractor remains fully responsible for ensuring contract performance pending completion of background investigations of Contractor personnel. Employees that do not require access to CMS federally controlled information systems, facilities, or sensitive information in order to perform their duties may begin work on a contract immediately and need not submit an HHS ID Badge Request.

i. Failure to cooperate with OPM or Agency representatives during the background investigation process is considered grounds for removal from the contract.

ii. DPS may provide written notification to the Contractor employee, with a copy to the COR, of all suitability/non-suitability decisions. A CMS adjudicative decision (based on criminal history results or completed investigation results) is final, and is not subject to appeal.

iii. Contractor personnel for whom DPS determines to be ineligible for ID issuance will be required to cease working on the contract immediately.

iv. The Contractor shall immediately submit an adverse information report, in writing to the CO with a copy to the COR, of any adverse information regarding any of its employees that may impact their ability to perform under this contract. Reports should be based on reliable and substantiated information, not on rumor or innuendo. The report shall include, at a minimum, the Contractor employee's name and associated contract number along with the adverse information. The COR will forward the adverse information report to the DPS for review and/or action.

v. At the Agency’s discretion, Contractor personnel may be provided an opportunity to explain or refute unfavorable information before an adjudicative decision is rendered on whether or not to withdraw the Federal ID from the individual in question. Under the provision of the Privacy Act of 1974, Contractor personnel may request a copy of their own investigation by submitting a written request to the OPM Federal Investigative Services (FIS) Freedom of Information (FOI) office. The following OPM-FOI link is being provided to afford one the instructions for obtaining a copy of one’s file: https://www.opm.gov/investigations/freedom-of-information-and-privacy-act-requests/.

g. Background Investigation Cost

The government will bear the cost of background investigations that are performed at the direction of CMS’ personnel security representatives by the Federal government’s approved and designated background investigation service provider, the OPM.

At the Agency's discretion, if an investigated Contractor employee leaves the employment of the Contractor, or otherwise is no longer associated with the contract within one (1) year from the date the background investigation was completed, the Contractor may be required to reimburse CMS for the full cost of the investigation. Depending upon the type of background investigation conducted and the cost incurred by CMS, the Contractor cost will be determined based upon the current OPM fiscal year billing rates, which can be found at http://www.opm.gov/investigations/background-investigations/federal-investigations-notices. The amount to be paid by the Contractor shall be due and payable when the CO submits a written letter notifying the Contractor as to the cost of the investigation. The Contractor shall pay the amount due within thirty (30) days of the date of the CO's letter by check, made payable to the "United States Treasury." The Contractor shall provide a copy of the CO's letter as an attachment to the check and submit both to the Office of Financial Management at the following address:

Centers for Medicare & Medicaid Services PO Box 7520 Baltimore, Maryland 21207

h. Identification Card Custody and Control

The Contractor is responsible for the custody and control of all forms of Federal identification issued by CMS to Contractor employees. The Contractor shall immediately notify the COR when a Contractor employee no longer requires agency access due to transfer, completion of a project, retirement, removal from work on the contract, or termination of employment. Return all CMS Federal ID cards to:

The Centers for Medicare and Medicaid Services Attn: DPS, Mailstop: SL-17-06 7500 Security Boulevard Baltimore, Maryland 21244

The Contractor shall also ensure that Contractor employees comply with CMS requirements concerning the renewal, loss, theft, or damage of an ID card.

Failure to comply with the requirements for custody and control of CMS issued ID cards may result in a delay in withholding final payment or contract termination, based on the potential for serious harm caused by inappropriate access to CMS facilities, sensitive information, information systems or other CMS resources.

i. Renewal: A Contractor employee’s CMS issued ID card is valid for a maximum of five (5) years and 9 months or until the contract expiration date (including option periods), whichever occurs first. The renewal process should begin six weeks before the ID card expiration date by contacting the COR. If an ID card is not renewed before it expires, the Contractor employee will be required to sign-in daily for facility access and may have limited access to information systems and other resources. Contractor ID card certificate(s) require yearly updates from the issuance date. The yearly updates should be coordinated between the contractor and the COR.

ii. Lost/Stolen: Immediately upon detection that an ID card is lost or stolen, the Contractor or Contractor employee shall report a lost or stolen ID card to the COR and the local security servicing organization at SECURITY@cms.hhs.gov. The Contractor shall also submit an Incident Report within 48 hours, to the COR, DPS at Badging@cms.hhs.gov, and the local security servicing organization. The Incident Report shall describe the circumstances of the loss or theft. If the loss or theft is reported by the Contractor to the local police, a copy of the police report shall be provided to the COR. The Contractor employee shall sign in daily for facility access and may have limited access to information systems and other resources until the replacement card is issued.

iii. Replacement: An ID card will be replaced if it is damaged, contains incorrect data, or is lost or stolen for more than three (3) days, provided there is a continuing need for agency access to perform work under the contract.

In the event that the PIV card or certificate(s) are not renewed in a timely fashion, or the ID card requires replacement due to being lost, stolen, or damaged, the contractor employee will go through the “Badge Issuance” process again as described in above in section (c)(2). In any of these events, contact your COR to coordinate the appropriate next steps.

i. Surrender ID Cards/Access Cards, Government Equipment

CMS reserves the right to suspend or withdraw ID card access at any time for any reason. Access will be restored upon the resolution of the issue(s).

Upon notification that routine access to CMS facilities, sensitive information, federally controlled information systems or other CMS resources is no longer required, the Contractor shall surrender the CMS issued ID card, access card, keys, computer equipment, and other government property to the CMS COR or directly to CMS at the address referenced above in section (f).

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.